INFSA-2025:15782: kernel security update
Information about definition
Identificator: INFSA-2025:15782
Type: security
Release date: 2025-10-14 17:44:57 UTC
Information about package
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Vulnerabilities description
- CVE-2025-38500
In the Linux kernel, the following vulnerability has been resolved: xfrm: interface: fix use-after-free after changing collect_md.
- CVE-2025-38550
In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: аn IPv6 MLD bookkeeping bug freed pmc->idev before it was used in ip6_mc_clear_src(), causing a use-after-free in the multicast code path. A remote attacker on the same L2 segment could potentially trigger a kernel crash via crafted MLD activity, leading to DoS.
- CVE-2025-38392
In the Linux kernel, the following vulnerability has been resolved: idpf: convert control queue mutex to a spinlock.
- CVE-2025-38332
In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Use memcpy() for BIOS version.
- CVE-2025-38498
In the Linux kernel, the following vulnerability has been resolved: do_change_type(): refuse to operate on unmounted/not ours mounts.
- CVE-2025-22068
In the Linux kernel, the following vulnerability has been resolved: ublk: make sure ubq->canceling is set when queue is frozen.
- CVE-2025-38463
In the Linux kernel, the following vulnerability has been resolved: tcp: Correct signedness in skb remaining space calculation.
- CVE-2025-39770
In the Linux kernel, the following vulnerability has been resolved: net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM.
Severity level
| CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
|---|---|---|---|
|
NIST — CVE-2025-22068
|
no information | 6.7 | no information |
|
NIST — CVE-2025-38332
|
no information | 7.0 | no information |
|
NIST — CVE-2025-38392
|
no information | 7.3 | no information |
|
NIST — CVE-2025-38463
|
no information | 7.3 | no information |
|
NIST — CVE-2025-38498
|
no information | 7.3 | no information |
|
NIST — CVE-2025-38500
|
no information | 7.8 | no information |
|
NIST — CVE-2025-38550
|
no information | 7.1 | no information |
|
NIST — CVE-2025-39770
|
no information | 5.7 | no information |
Updated packages